EnvoyMesh: A Self-Hosted P2P Network for AI Agents and Private Chat
Decentralized P2P mesh for autonomous AI agents — self-sovereign identity, peer-to-peer chat, and on-device AI that negotiates tasks on your behalf. No central server.
At a glance
- What is it?
- EnvoyMesh is a decentralized peer-to-peer mesh built on libp2p where your devices run the network and your cryptographic identity belongs to you. It combines private messaging, voice calls, file sharing, a knowledge base with federated RAG, and an on-device AI agent that negotiates tasks on your behalf, all without a central server.
- Who is it for?
- EnvoyMesh suits developers who want a self-hosted private network where their AI agent operates on their own hardware rather than someone else's infrastructure. The project is actively developed with releases as recent as 2026-09-26.
- Can I use it commercially?
- Not without permission. GitHub finds no licence file in the repository, and without a licence all rights are reserved by default: you may read the code but not reuse it. Check the README, or ask the authors, before using it.
- Is it still maintained?
- Yes. The repository last received commits 3 days ago.
- What is it written in?
- Mainly TypeScript, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 28, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What EnvoyMesh Replaces and Why
Most social apps and AI assistants route messages and model calls through a central server. The operator of that server holds your message history, your identity, and your agent's context. EnvoyMesh flips this arrangement: your devices run the network, your identity is an Ed25519 key pair that you control, and your AI agent runs on your hardware under your policies.
The practical problem it solves is privacy and ownership in AI-assisted communication. A team or family that wants peer-to-peer messaging, a shared knowledge base, and AI agent collaboration without a platform intermediary has few options today. EnvoyMesh is built specifically for that use case.
Two Protocols: Mesh and Thin Client
EnvoyMesh defines two distinct protocols. The mesh protocol runs on libp2p and governs how home nodes communicate with each other using signed envelopes. Home nodes exchange envelopes for peer discovery, bond management, chat, knowledge base queries, and agent task negotiation. Relay nodes assist with connectivity but do not read the payload content.
The thin-client protocol governs communication between a desktop home node and a phone. The desktop runs the full node, holding model keys and repositories. EnvoyGo (the phone companion app) and EnvoyDev Mobile connect as thin clients over JSON-RPC on WebSocket or libp2p. This separation means that adding a phone does not mean running a full node on the phone; the phone delegates to the desktop for storage-heavy and compute-heavy operations.
The default home node is a standalone desktop application available for macOS (Apple Silicon DMG) and Windows (EXE). A headless home node using LaunchAgent or a logon task is documented for advanced operators who want the node running as a background service. Linux requires building from source.
Identity, Bonds, and Trust Tiers
Every participant in the mesh has a self-sovereign DID backed by an Ed25519 key pair. There is no account to create or lose: your identity is the key. Contacts are managed through a bonding mechanism with four trust tiers: blocked, public, referred, and direct. Each tier controls what a contact can access: public contacts see only your public knowledge items and are subject to a rate limit on knowledge queries, while direct contacts have broader access.
The trust tier system means that the agent operating on your behalf also enforces your policies. When your AI agent receives a task negotiation request from a bonded peer, it acts within the rules you have defined for that contact's tier. The README describes the agent as able to make friends, search knowledge, and execute tasks within your safety rules.
Self-sovereign identity has a real practical implication: if you lose your keys, you lose your identity in the mesh. There is no password reset mechanism in a system without a central server. Key backup is the operator's responsibility.
Installing and Starting a Home Node
The desktop home node is the entry point. Install it from the GitHub Releases page or the project mirrors for macOS or Windows. The macOS build is a DMG for Apple Silicon. The Windows build is an EXE installer.
For developers building on EnvoyMesh from source, the repository uses Node 22.13.0 or higher, pnpm workspaces, and a setup script:
bash scripts/setup.shA Windows PowerShell equivalent is available:
powershell -ExecutionPolicy Bypass -File scripts/setup.ps1OpenClaw installs via a separate script:
bash scripts/install-openclaw.shThe built-in AI engine (EnvoyAI / OpenClaw) starts automatically with the node on port 18789. The configuration file at .env.example covers the full environment variable set, including ENVOYMESH_PROFILE for the key and data directory, ENVOYMESH_VAULT for the knowledge file root, and ENVOYMESH_DISCOVERY_PROFILE for network topology choices (lan-fast, wan-default, relay-only, or contacts-only).
Knowledge Base, Federated RAG, and Obsidian Integration
The built-in knowledge base is a Markdown editor with per-item sensitivity labels: public, friends, or private. Changes trigger automatic RAG re-indexing on save. The public sub-graph is queryable by any peer, bonded or stranger, with a per-stranger rate limit.
Federated RAG fans queries out to bonded peers' knowledge libraries and synthesizes answers from multiple sources. This is the mechanism that allows an AI agent to answer questions by drawing on knowledge distributed across multiple participants in the mesh rather than only local data.
The optional kb-obsidian provider syncs an Obsidian vault into the knowledge base. The integration reads frontmatter YAML, wiki-links graph structure, and a published: true/false flag that maps to the sensitivity label. The agent can write discoveries back to the vault as notes with source attribution via MCP write-back.
External Agent Bridge and AI Engine Options
The built-in AI engine is EnvoyAI, which runs as OpenClaw on port 18789. An external agent bridge allows connecting HomeClaw, Hermes, OpenHuman, or any HTTP agent as a second engine, configured under Settings in the AI section. Four operating modes are available: built-in only, built-in plus external, external only, or none.
The coding tab integrates Envoy Harness and Pi as built-in coding agents, with Claude Code, Codex, Cursor, and OpenCode supported when they are installed on the home computer. This tab organizes projects, tasks, and coding agents in one place rather than running them from a separate terminal.
A significant limitation: the repository license is not specified. The GitHub repository page shows NOASSERTION for the license field. Before using EnvoyMesh in any commercial context, the license terms need to be confirmed directly with the project.
Maintenance Status and Release History
The last push to the repository was on 2026-09-22. The most recent release, EnvoyMesh-0.6.0, was published on 2026-09-26. Prior releases include EnvoyMesh-0.5.0 on 2026-09-10 and EnvoyMesh-0.4.2 on 2026-09-04, indicating a rapid release cadence. Guidebooks for versions 0.2.2, 0.3.0, and 0.4.0 are checked into the repository root as Markdown and HTML files, giving a historical record of the protocol evolution.
A companion app, EnvoyDev, and a notes application called Veda Notes are listed as apps built on the same protocols. EnvoyGo is available on the iOS App Store (iOS 18.6 or higher) and the Google Play Store, with an APK mirror also available.
Editorial conclusion
EnvoyMesh suits developers who want a self-hosted private network where their AI agent operates on their own hardware rather than someone else's infrastructure. The project is actively developed with releases as recent as 2026-09-26. The trade-off is setup complexity: you run a desktop home node as the always-on anchor, pair mobile devices to it, and manage your own identity keys. The license is not documented in the repository, which is a real concern for commercial deployments. Before building on EnvoyMesh, clarify the licensing terms and verify that your team can operate and maintain a libp2p node at the reliability level your use case requires.
Frequently asked questions
Does EnvoyMesh require a central server?
No. EnvoyMesh uses libp2p for peer discovery and message routing. Relay nodes assist with connectivity for peers behind NAT, but they do not read message payloads. Your home node is the only required persistent component, and it runs on your own hardware.
What AI agents can run inside EnvoyMesh?
The built-in engine is EnvoyAI, running as OpenClaw on port 18789. The external agent bridge supports HomeClaw, Hermes, OpenHuman, and any HTTP agent. When installed on the home computer, Claude Code, Codex, Cursor, and OpenCode integrate with the coding tab.
What is the EnvoyMesh license?
The repository reports NOASSERTION for the license field, meaning no recognized open-source license has been identified. Before using EnvoyMesh in any commercial project, the license terms need to be confirmed directly with the author.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/allenpeng0705-envoymesh)